Campus network multi-terminal roaming authentication-free method and device

By setting up roaming groups and virtual ONU devices in the campus network, users can do not need to repeat authentication when switching terminals or network environments, which solves the problem of frequent authentication in the existing technology and improves the convenience of using the campus network.

CN119967410AActive Publication Date: 2025-05-09WUHAN GREENET INFORMATION SERVICE
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202411977963.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-05-09
Estimated Expiration
2044-12-31

AI Technical Summary

Technical Problem

The existing campus network technology requires users to frequently perform portal authentication when switching terminals or network environments, resulting in inconvenience in user network use.

Method used

By reserving the binding page entrance on the portal page, the user enters the MAC addresses of multiple terminals and selects the roaming sub-region. The access cloud gateway sets up a roaming group for multiple terminals, including the terminal MAC address, roaming sub-region information, actual ONU device information and virtual ONU device information, to realize the unique virtual ONU device of the roaming group and avoid repeated authentication.

Benefits of technology

It realizes that multiple terminals do not require repeated authentication in the same roaming area, which improves the convenience of using the campus network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119967410A_ABST
    Figure CN119967410A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of campus networks, and provides a campus network multi-terminal roaming authentication-free method and device. The method comprises the following steps: setting a roaming group for a plurality of terminals in an access cloud gateway according to mac addresses of the plurality of terminals and selected roaming sub-regions; the access cloud gateway judges whether the first user is an authenticated user in a roaming area where the first ONU equipment is located according to the mac address of the first terminal in the second uplink message, the related information of the first ONU equipment and each roaming group; and if the user is judged to be an authenticated user, packaging the second uplink message into a third uplink message which can be identified by the wide area network according to the related information of the virtual ONU equipment in the roaming group to which the first ONU equipment belongs, and transmitting the third uplink message to the network. According to the invention, through setting the roaming group of the plurality of terminals and the virtual ONU equipment, the whole roaming group only has one ONU equipment externally, so that repeated authentication is not needed, and authentication-free roaming of the campus network of the plurality of terminals is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of campus network, and in particular to a method and device for multi-terminal roaming authentication-free in a campus network. Background Art

[0002] In the past campus network scenario, if a user terminal wanted to access the Internet, it had to first log in and verify at the edge portal server to find the user link to access the Internet; once the user terminal switched the network environment, such as switching to another dormitory or teaching building, the optical network unit (ONU) device connected to it changed, so it was necessary to re-perform portal authentication, delete the binding rules of the last login authentication, and bind to the new link before it could use the network again. This resulted in users having to frequently perform portal authentication when they were on campus, which brought trouble to their network use.

[0003] Furthermore, in actual use, there is often a situation where a campus network user has multiple terminals, such as a laptop computer, a mobile phone terminal and a tablet terminal. In the prior art, every time the user switches terminals to use the campus network, re-authentication is required.

[0004] In view of this, overcoming the defects of the prior art is an urgent problem to be solved in the field of this technology. Summary of the invention

[0005] The technical problem to be solved by the present invention is to provide a method and device for multi-terminal roaming without authentication in a campus network, so that multiple terminals do not need to perform repeated authentication when using the campus network in the same roaming area.

[0006] The present invention adopts the following technical solution:

[0007] In a first aspect, the present invention provides a campus network multi-terminal roaming authentication-free method, comprising:

[0008] A binding page entrance is reserved in the portal page, so that after the user successfully authenticates and logs in using the corresponding terminal, the user can enter the binding page from the binding page entrance, enter the MAC addresses of multiple terminals owned by the user on the binding page, and select one or more roaming sub-areas;

[0009] According to the MAC addresses of the multiple terminals and the selected roaming sub-areas, a roaming group is set for the multiple terminals in the access cloud gateway; wherein the roaming group includes the MAC addresses of the multiple terminals, relevant information of the selected multiple roaming sub-areas, relevant information of each actual ONU device in the selected multiple roaming sub-areas, and relevant information of the unique virtual ONU device of the roaming group;

[0010] When the first ONU device receives the first uplink message from the first terminal, it adds relevant information of the first ONU device to the first uplink message, generates a second uplink message, and sends the second uplink message to the access cloud gateway; wherein the first uplink message also carries the mac address of the first terminal;

[0011] The access cloud gateway determines whether the first user is an authenticated user in the roaming area where the first ONU device is located according to the MAC address of the first terminal carried in the second uplink message, the relevant information of the first ONU device, and each roaming group; wherein the first user is the user to which the first terminal belongs;

[0012] If it is determined that the first user is an authenticated user in the roaming area where the first ONU device is located, the second uplink message is encapsulated into a third uplink message recognizable by the wide area network according to the relevant information of the virtual ONU device in the roaming group to which the first ONU device belongs, and the third uplink message is transmitted to the network.

[0013] Preferably, the relevant information of the actual ONU device includes the VNI identifier of the actual ONU device and the QinQ information of the actual ONU device; the relevant information of the virtual ONU device includes the virtual VNI identifier and the virtual QinQ information;

[0014] The access cloud gateway includes a virtual switch and a virtual client device, and the step of setting a roaming group for the multiple terminals in the access cloud gateway according to the MAC addresses of the multiple terminals and the selected roaming sub-areas specifically includes:

[0015] Storing roaming group information items, ONU device information items, and account roaming information items in the virtual client device;

[0016] The roaming group information table entry stores the ID number of each roaming group, the ID number of each roaming sub-area, and the virtual VNI identifier and virtual QinQ information corresponding to each roaming group;

[0017] The ONU device information table item stores the VNI identification of each actual ONU device, the QinQ information of each actual ONU device, and the ID number of the roaming sub-area to which each actual ONU device belongs;

[0018] The account roaming information table entry stores the MAC addresses of the terminals bound to the user, the user's account information, and the ID number of the bound roaming group.

[0019] Preferably, the access cloud gateway determines whether the first user is an authenticated user in the roaming area where the first ONU device is located according to the mac address of the first terminal carried in the second uplink message, the relevant information of the first ONU device, and each roaming group, specifically including:

[0020] The virtual switch receives the second uplink message, and forwards the second uplink message to the virtual client device;

[0021] The virtual client device finds the first roaming group bound to the first terminal from the account roaming information entry according to the MAC address of the first terminal carried in the second uplink message, and finds the first account information of the user to which the first terminal belongs;

[0022] Acquire, from the ONU device information table entry, a first roaming sub-area to which the first ONU device belongs, according to the VNI identifier of the first ONU device and the QinQ information of the first ONU device carried in the second uplink message;

[0023] searching, according to the roaming group information table item, whether the first roaming group includes the first roaming sub-area, and if it is found that the first roaming group includes the first roaming sub-area, searching whether there is historical login information of the first account information in the first roaming group;

[0024] If the historical login information exists, it is determined that the first user is an authenticated user in the roaming area where the first ONU device is located.

[0025] Preferably, the historical login information is recorded when the terminal bound to the user performs historical authentication login in the roaming sub-area included in the first roaming group, and specifically includes:

[0026] When the virtual client device determines that the first user is not an authenticated user in the roaming area where the first ONU device is located, redirecting the second uplink message to the portal server so that the portal server feeds back a portal authentication page to the first terminal;

[0027] After the first terminal successfully logs in and authenticates on the portal authentication page, the portal server returns an authentication success message to the virtual client device; wherein the authentication success message carries the account information used for authentication, the VNI identifier of the ONU device currently accessed by the first terminal, and the QinQ information of the ONU device currently accessed by the first terminal;

[0028] The virtual client finds the corresponding roaming sub-area from the ONU device information table item according to the VNI identifier of the ONU device currently accessed by the first terminal and the QinQ information of the ONU device currently accessed by the first terminal; and searches the roaming group including the roaming sub-area from the roaming group information table item according to the roaming sub-area;

[0029] The ID number of the roaming group and the account information are recorded as historical login information in the authentication table; wherein, for one account information, only the latest historical login information is recorded in the authentication table.

[0030] Preferably, encapsulating the second uplink message into a third uplink message identifiable by the wide area network according to the relevant information of the virtual ONU device in the roaming group to which the first ONU device belongs specifically includes:

[0031] Find the corresponding WAN side VNI identifier and WAN side QinQ information according to the virtual ONU device related information in the roaming group to which the first ONU device belongs;

[0032] The WAN side VNI identifier and the WAN side QinQ information are used to replace the virtual ONU device related information in the second uplink message to generate the third uplink message.

[0033] Preferably, the method further comprises:

[0034] IOMP sets an address pool for each roaming group; the addresses in each address pool extend to segment B;

[0035] According to the MAC address of the first terminal and the related information of the first ONU device carried in the second uplink message, a corresponding address is taken from the address pool of the corresponding roaming group and allocated to the first terminal.

[0036] Preferably, the method further comprises: setting the same SSID for all ONU devices located in a roaming area.

[0037] Preferably, the method further comprises:

[0038] Set the option82_sensitive value of the roaming area in the access cloud gateway to 0 so that when the option82 field in the message sent by different ONU devices changes, the dial-up is not re-performed.

[0039] In a second aspect, the present invention further provides a campus network multi-terminal roaming authentication-free device, which is used to implement the campus network multi-terminal roaming authentication-free method described in the first aspect, and the device includes:

[0040] At least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the processor to execute the method for multi-terminal roaming in a campus network without authentication as described in the first aspect.

[0041] In a third aspect, the present invention further provides a non-volatile computer storage medium, wherein the computer storage medium stores computer executable instructions, and the computer executable instructions are executed by one or more processors to complete the method described in the first aspect.

[0042] In a fourth aspect, a chip is provided, comprising: a processor and an interface, for calling and running a computer program stored in the memory from a memory, and executing any method of the first aspect.

[0043] In a fifth aspect, a computer program product comprising instructions is provided, which, when executed on a computer or a processor, causes the computer or the processor to execute any method as described in the first aspect.

[0044] The present invention sets a roaming group and a virtual ONU device, and after verifying that the first user is an authenticated user, uses the virtual ONU device related information to generate WAN side information, so that the entire roaming group appears to the outside as having only one ONU device (i.e., the virtual ONU device), and thus there is no need for repeated authentication, but the original link is used for network communication, thereby realizing campus network roaming without authentication, and the roaming group allows binding of multiple terminals of the user, so that multiple terminals do not need to be repeatedly authenticated when using the campus network in the same roaming area, further improving the convenience of using the campus network. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments of the present invention. Obviously, the drawings described below are only some embodiments of the present invention, and for ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0046] Figure 1 It is a flowchart of a first campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;

[0047] Figure 2 It is a schematic diagram of a portal authentication page in a campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;

[0048] Figure 3It is a schematic diagram of a portal authentication page in a campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;

[0049] Figure 4 It is a schematic diagram of a binding page in a campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;

[0050] Figure 5 It is a schematic diagram of a roaming group information table item in a campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;

[0051] Figure 6 It is a flow chart of a second campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;

[0052] Figure 7 It is a schematic diagram of an account roaming information table item in a campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;

[0053] Figure 8 It is a flowchart of a third campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;

[0054] Fig. 9 It is a flowchart of a fourth campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;

[0055] Fig.10 It is a flowchart of a fifth campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;

[0056] Fig.11 It is a schematic diagram of a campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;

[0057] Fig.12 It is a schematic diagram of a campus network multi-terminal roaming authentication-free method provided by an embodiment of the present invention;

[0058] Fig.13 The present invention is a schematic diagram of the architecture of a device for multi-terminal roaming without authentication in a campus network provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0059] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0060] Unless the context requires otherwise, throughout the specification and claims, the term "including" is to be interpreted as open inclusion, that is, "including, but not limited to". In the description of the specification, the terms "one embodiment", "some embodiments", "exemplary embodiments", "examples", "specific examples" or "some examples" and the like are intended to indicate that specific features, structures, materials or characteristics associated with the embodiment or example are included in at least one embodiment or example of the present disclosure. The schematic representation of the above terms does not necessarily refer to the same embodiment or example. In addition, the specific features, structures, materials or characteristics may be included in any one or more embodiments or examples in any appropriate manner, that is, although they may be carried in the embodiments or examples of the above terms due to reasons such as the order and position of appearance, it is not limited to that they can be carried in combination by one embodiment or example.

[0061] In the description of the present invention, the terms "first" and "second" are used only for descriptive purposes, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of indicated technical features. Thus, the features defined as "first" and "second" may explicitly or implicitly include one or more of the features. In the description of the embodiments of the present disclosure, unless otherwise specified, the meaning of "multiple" is two or more. In addition, for example, the same type of nouns may be described as two independent individuals by adding "A" and "B" at the end. In this case, the corresponding features defined as "A" and "B" are only used to distinguish the same type of individuals for description purposes, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of indicated technical features.

[0062] In the description of the present invention, the expression "A and / or B" (where A and B are used to formally represent specific characteristic contents) will be involved, and the corresponding expressions include the following three combinations: only A, only B, and a combination of A and B.

[0063] As used herein, "about," "substantially," or "approximately" includes the stated value and an average value that is within an acceptable range of deviation from the particular value as determined by one of ordinary skill in the art taking into account the measurements in question and the errors associated with the measurement of the particular quantity (i.e., the limitations of the measurement system).

[0064] In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.

[0065] Embodiment 1:

[0066] Embodiment 1 of the present invention provides a campus network multi-terminal roaming authentication-free method, such as Figure 1 As shown, including:

[0067] In step 201, a binding page entrance is reserved in the portal page, so that after the user successfully authenticates and logs in using the corresponding terminal, the user can enter the binding page from the binding page entrance, enter the MAC addresses of multiple terminals owned by the user on the binding page, and select one or more roaming sub-areas; wherein the binding page entrance is displayed after the user is successfully authenticated, such as Figure 2 This is the portal page when the user has not logged in for authentication. Figure 3 Click the portal page after the user successfully logs in and authenticates. Figure 3 In "Roaming Management" (i.e. binding page entrance), enter Figure 4 The binding page shown allows the user to input multiple devices and select multiple roaming sub-areas to form a roaming group. Each roaming sub-area is pre-divided by a person skilled in the art according to the buildings inside the campus, such as dividing a building into a roaming sub-area.

[0068] In step 202, according to the MAC addresses of the multiple terminals and the selected roaming sub-areas, a roaming group is set for the multiple terminals in the access cloud gateway; wherein the roaming group includes the MAC addresses of the multiple terminals, relevant information of the selected multiple roaming sub-areas, relevant information of each actual ONU device in the selected multiple roaming sub-areas, and relevant information of a virtual ONU device unique to the roaming group; the relevant information can be understood as identification information for identifying the corresponding device, and the virtual ONU device can be understood as a device that is not actually present in the network, but a virtual device for representing all actual ONU devices in the corresponding area, and the virtual device has the same type of relevant information as the actual ONU device. For example, if the identification information of the actual ONU device includes a VNI identifier (full name: VXLAN Network Identifier, Chinese meaning: identifier in the VXLAN network) and QinQ information, then the virtual ONU device also has a VNI identifier and QinQ information (i.e., the virtual ONU device related information), and is different from other virtual ONU devices and actual ONU devices. The VNI identifier and QinQ information of the virtual ONU device are allocated when the roaming group is established.

[0069] In step 203, when the first ONU device receives the first uplink message from the first terminal, it adds the relevant information of the first ONU device to the first uplink message, generates a second uplink message, and sends the second uplink message to the access cloud gateway; wherein the first uplink message also carries the mac address of the first terminal; the first ONU device is the ONU device accessed by the first terminal. In actual use, a roaming group also corresponds to a tunnel group (also called an EVPN instance group), which includes the tunnels (also called EVPN instances) used by each ONU device bound to the roaming group to transmit messages. The tunnel is used to isolate the messages of different roaming groups, that is, to isolate the messages. For example, the IP and QinQ information of the messages in different tunnels can be repeated. If there is no tunnel isolation, the IP and QinQ information of the messages will be repeated, which will cause confusion in the identification of the traffic. The ID of the tunnel group (also called LAN_EVPN_Group) is also added to the second uplink message.

[0070] In step 204, the access cloud gateway determines whether the first user is an authenticated user in the roaming area where the first ONU device is located based on the MAC address of the first terminal carried in the second uplink message, the relevant information of the first ONU device, and the roaming groups; wherein the first user is the user to which the first terminal belongs; that is, whether the first user has performed portal authentication in the roaming area and the authentication information is still valid.

[0071] In step 205, if it is determined that the first user is an authenticated user in the roaming area where the first ONU device is located, the second uplink message is encapsulated as a third uplink message recognizable by the wide area network according to the virtual ONU device related information in the roaming group to which the first ONU device belongs, and the third uplink message is transmitted to the network. If it is determined that the first user is not an authenticated user in the roaming area where the first ONU device is located, redirect to the portal authentication page so that the user can perform authentication.

[0072] Among them, according to the relevant information of the virtual ONU device in the roaming group to which the first ONU device belongs, the second uplink message is encapsulated as a third uplink message identifiable by the wide area network, specifically including: finding the corresponding wide area network (abbreviated as: WAN) side VNI identifier and WAN side QinQ information according to the relevant information of the virtual ONU device in the roaming group to which the first ONU device belongs; using the WAN side VNI identifier and WAN side QinQ information to replace the virtual ONU device related information in the second uplink message to generate the third uplink message.

[0073] The access cloud gateway includes a virtual switch and a virtual client device, and the process of generating the third uplink message is mainly completed by the virtual client device. In the virtual client device, a virtual ONU device corresponds to a unique local area network (abbreviated as: LAN) side VNI identifier and LAN side QinQ information, WAN side VNI identifier and WAN side QinQ information.

[0074] This embodiment sets up a roaming group and a virtual ONU device, and after verifying that the first user is an authenticated user, uses the virtual ONU device related information to generate WAN side information, so that the entire roaming group appears to the outside as having only one ONU device (i.e., the virtual ONU device), and there is no need for repeated authentication. Instead, the original link is used for network communication, thereby realizing authentication-free roaming in the campus network. In addition, the roaming group allows binding of multiple terminals of the user, so that multiple terminals do not need to be repeatedly authenticated when using the campus network in the same roaming area, further improving the convenience of using the campus network.

[0075] In actual use, different ONU devices have different service set identifiers (SSIDs), which may also trigger the first terminal to re-dial authentication. Therefore, the method further includes: setting the same SSID for all ONU devices in a roaming area.

[0076] Moreover, when the terminal roams between authentication-free ONUs, the option82 reported by the optical line terminal (OLT) device will report different information according to the physical location of the ONU connected to the OLT device. In the prior art, when the cloud gateway detects that the option82 of the same account is different, it will initiate a redial, which causes the terminal to still need to dial frequently when roaming between authentication-free ONUs. In order to solve this problem, the method also includes: setting the value of option82_sensitive in the roaming area of ​​the access cloud gateway to 0, so that when the option82 field in the message sent by different ONU devices changes, the dialing is not re-dialed. Among them, option82_sensitive can be understood as a field used to identify whether the dialing action is sensitive to the option82 field, that is, when the value of option82_sensitive is 1, it is sensitive to the option82 field, and the dialing is re-dial when the option82 field is detected to change; when the value of option82_sensitive is 0, it is not sensitive to the option82 field, and the dialing is not re-dial when the option82 field is detected to change.

[0077] In addition, if the operator has performed precise binding on the Authentication, Authorization, Accounting (AAA) server, the physical scope of the roaming area needs to be limited according to the precise binding conditions. For example, if AAA has performed precise binding on the OLT device, the Passive Optical Network (PON) board, and the PON port, then these ONUs in a roaming area need to be on the same PON board of the same OLT and on the same PON port.

[0078] In the actual application scenario, the relevant information of the actual ONU device includes the VNI identifier of the actual ONU device and the QinQ information of the actual ONU device; the relevant information of the virtual ONU device includes the virtual VNI identifier and the virtual QinQ information; it should be noted that the VNI identifier of the actual ONU device and the QinQ information of the actual ONU device, the virtual VNI identifier and the virtual QinQ information all refer to the LAN side VNI identifier and the LAN side QinQ information. In actual use, the QinQ information is also manifested as Network Address Translation (NAT) plus QinQ.

[0079] The access cloud gateway includes a virtual switch and a virtual client device, the virtual switch is also called vSwitch, and the virtual client device is also called vCPE. According to the MAC addresses of the multiple terminals and the selected roaming sub-area, a roaming group is set for the multiple terminals in the access cloud gateway, which specifically includes: storing roaming group information items, ONU device information items and account roaming information items in the virtual client device.

[0080] The roaming group information table entry stores the ID number of each roaming group, the ID number of each roaming sub-area, and the virtual VNI identifier and virtual QinQ information corresponding to each roaming group, such as Figure 5 As shown, the roaming group ID is a unique index.

[0081] The ONU device information table item stores the VNI identification of each actual ONU device, the QinQ information of each actual ONU device, and the ID number of the roaming sub-area to which each actual ONU device belongs. Figure 6 As shown; wherein, the VNI identifier of the actual ONU device and the QinQ information of each actual ONU device are used as the unique index, and each actual ONU device corresponds to a unique roaming sub-area (expressed as the ID number of the roaming sub-area).

[0082] The account roaming information table entry stores the MAC address of each terminal bound to the user, the user's account information, and the ID number of the bound roaming group, such as Figure 7 As shown. The mac address is a unique index, corresponding to a roaming group. In actual use, when the user selects one or more corresponding roaming sub-areas, first determine whether the selected roaming sub-area corresponds to an existing roaming group. If there is a corresponding existing roaming group, directly add the mac addresses of the terminals bound to the user, the user's account information and the ID number of the existing roaming group to the account roaming information table item; if there is no corresponding existing roaming group, generate a new roaming group, add the ID number of the new roaming group, the ID number of each roaming sub-area in the new roaming group, and the virtual VNI identifier and virtual QinQ information corresponding to the new roaming group to the roaming group information table item, and add the mac addresses of the terminals bound to the user, the user's account information and the ID number of the new roaming group to the account roaming information table.

[0083] The access cloud gateway determines whether the first user is an authenticated user in the roaming area where the first ONU device is located according to the MAC address of the first terminal carried in the second uplink message, the relevant information of the first ONU device, and each roaming group, such as Figure 8 As shown, specifically including:

[0084] In step 301, the virtual switch receives the second uplink message, and forwards the second uplink message to the virtual client device.

[0085] In step 302, the virtual client device finds the first roaming group bound to the first terminal from the account roaming information entry according to the MAC address of the first terminal carried in the second uplink message, and finds the first account information of the user to which the first terminal belongs.

[0086] In step 303, according to the VNI identifier of the first ONU device and the QinQ information of the first ONU device carried in the second uplink message, the first roaming sub-area to which the first ONU device belongs is obtained from the ONU device information table item.

[0087] In step 304, based on the roaming group information table item, it is searched whether the first roaming group includes the first roaming sub-area. If it is found that the first roaming group includes the first roaming sub-area, it can be considered that the current access location is located in the first roaming group bound to the first terminal, then it is searched whether there is historical login information of the first account information in the first roaming group.

[0088] In step 305, if the historical login information exists, it is determined that the first user is an authenticated user in the roaming area where the first ONU device is located. If the first roaming group does not include the first roaming sub-area, or there is no historical login information, redirect to the portal authentication page for re-authentication.

[0089] The historical login information is recorded when the terminal bound to the user performs historical authentication login in the roaming sub-area included in the first roaming group, such as Fig. 9 As shown, specifically including:

[0090] In step 401, when the virtual client device determines that the first user is not an authenticated user in the roaming area where the first ONU device is located, the second uplink message is redirected to the portal server so that the portal server feeds back a portal authentication page to the first terminal.

[0091] In step 402, after the first terminal successfully logs in and authenticates on the portal authentication page, the portal server returns an authentication success message to the virtual client device; wherein the authentication success message carries the account information used for authentication, the VNI identifier of the ONU device currently accessed by the first terminal, and the QinQ information of the ONU device currently accessed by the first terminal.

[0092] In step 403, the virtual client finds the corresponding roaming sub-area from the ONU device information table item according to the VNI identifier of the ONU device currently accessed by the first terminal and the QinQ information of the ONU device currently accessed by the first terminal; and searches for the roaming group including the roaming sub-area from the roaming group information table item according to the roaming sub-area.

[0093] In step 404, the ID number of the roaming group and the account information are recorded as historical login information in an authentication table; wherein, for one account information, only the latest historical login information is recorded in the authentication table.

[0094] In the prior art, the address pool is often implemented using the C segment, that is, the first three segments of the IP address are fixed, and the fourth segment is used for address allocation. The number of IP addresses that can be allocated by an address pool is 265, such as from 192.168.2.0 to 192.168.2.255. In a specific application scenario, since a roaming group corresponds to information related to a virtual ONU device, and in a campus network scenario, there are often many users, that is, many terminals. When there are many terminals bound to a roaming group, the IP addresses in the address pool may be exhausted, resulting in a situation where a valid address cannot be allocated to the terminal. In order to solve this problem, the method also includes:

[0095] The intelligent integrated management platform (IOMP) sets an address pool for each roaming group; wherein the address of each address pool extends to segment B, that is, the first two segments of the IP address are fixed, and the third and fourth segments are used for address allocation. At this time, the number of IP addresses that can be allocated by an address pool is 65535, such as from 192.168.0.0 to 192.168.255.255. According to the mac address of the first terminal and the relevant information of the first ONU device carried in the second uplink message, the corresponding address is taken from the address pool of the corresponding roaming group and allocated to the first terminal.

[0096] In actual use, the method also includes: the access cloud gateway also records the ONU device accessed when each terminal authenticates and logs in according to the authentication success message, and when it is monitored that the number of times the first terminal accesses the second ONU device is greater than the preset number of times, a reminder message is sent to the first terminal through the portal server; wherein, the second ONU device is an ONU device outside the roaming group of the first terminal, and the reminder message is used to prompt the user whether to add the current area to the roaming group; if the user chooses to add the current area to the roaming group according to the reminder message, the second ONU device is added to the roaming group of the first terminal.

[0097] Considering the actual application scenario, the area where students use the campus network for entertainment is mainly concentrated in the dormitory building. Generally speaking, in order to prevent the students' entertainment network from affecting their study and office network, a cloud gateway is often used to limit the network bandwidth of each dormitory, and a dormitory is used as a roaming sub-area to facilitate traffic isolation between dormitories. However, in this case, when a user in a dormitory needs to download a file, the file download task may affect the network speed of other users in the dormitory. In order to solve this problem, this embodiment provides an optimal campus network multi-terminal roaming authentication-free method, such as Fig.10 As shown, specifically including:

[0098] In step 501, the access cloud gateway monitors the downlink messages of each dormitory and determines whether each downlink message is a file download type message; wherein the file download type is a message used to transmit files downloaded by users from the network, and the downlink message refers to a message on the LAN side after the corresponding NAT conversion of the message received from the wide area network. The monitoring of the downlink messages of each dormitory specifically includes: pre-storing the corresponding relationship between each dormitory and the ONU device of each dormitory in the access cloud gateway. In actual use, the corresponding relationship is expressed as an ONU device information table item, and the ONU device information table item also includes a dormitory identification (which can be understood as a dormitory number). When the corresponding roaming sub-area carries a dormitory identification, the roaming sub-area can be regarded as a dormitory, and the specific dormitory is identified according to the dormitory identification.

[0099] When a downlink message is received, the ONU device to which the downlink message needs to be sent is identified according to the QinQ information carried in the downlink message, and the dormitory to which the downlink message belongs is found from the corresponding relationship according to the ONU device.

[0100] The determination of whether each downlink message is of the file download type may be performed by pre-analyzing the commonly used types of downlink messages in the network to obtain identification words in each type of downlink message, and then using the identification words to match the downlink messages received in actual use.

[0101] In step 502, when it is detected that there is a file download type message in the first dormitory, the destination terminal that the file download type message needs to reach is found, and it is found whether there is a second dormitory other than the first dormitory in the historically bound dormitory of the first user to which the destination terminal belongs; wherein the historically bound dormitory refers to the dormitory in the roaming group bound by the first user in history, and the roaming sub-areas added to the roaming group by the first user in history are all recorded in the access cloud gateway; for example, if the first user added dormitory A and dormitory B to the bound roaming group one month ago, deleted dormitory B and added dormitory C two weeks ago, dormitory A is the dormitory where the first user is currently located, that is, the first dormitory, then dormitory B and dormitory C can both be considered as the second dormitory; the second dormitory can be understood as a dormitory with close contacts with the first user in actual use. The destination terminal can be understood as the terminal of the first user.

[0102] In step 503, if it is found that there is a second dormitory, the bandwidth occupancy of the downlink message in the second dormitory is calculated. If the bandwidth occupancy of the downlink message in the second dormitory is less than the preset bandwidth, the file download type message received subsequently from the first dormitory is divided into a first message and a second message according to a preset quantity ratio; wherein the access cloud gateway does not include the second message in the statistics of the first dormitory traffic; the preset bandwidth and the preset quantity ratio are obtained by technical personnel in this field based on empirical analysis. When the bandwidth occupancy of the downlink message in the second dormitory is less than the preset bandwidth, it can be considered that the current bandwidth demand of each user in the second dormitory is relatively small and there is more idle bandwidth. The setting standard of the preset quantity ratio is: while using the bandwidth of the second dormitory to assist in file downloading, it does not affect the network demand of each user in the second dormitory.

[0103] In step 504, the first message is sent to the destination terminal along the original path, and the forwarding identifier, the IP address of the second message and the relevant information of the ONU device of the second dormitory are added to the second message to generate a third message; wherein the second message carries the IP address, MAC address and relevant information of the destination terminal; wherein the destination ONU device is the ONU device currently connected to the destination terminal.

[0104] In step 505, the third message is sent to the ONU device of the second dormitory. The ONU device of the second dormitory identifies the third message according to the forwarding identifier, and forwards the third message to the destination ONU device through the local area network according to the IP address, MAC address of the destination terminal and the relevant information of the destination ONU device in the third message, so that the destination ONU device restores the third message to the first message and transmits it to the destination terminal.

[0105] Among them, when the access cloud gateway limits the bandwidth of the dormitory, it mainly limits the external network traffic, that is, it limits the bandwidth of the traffic that needs to be transmitted to the wide area network. The usual implementation method is to discard the part of the received downlink message that exceeds the bandwidth according to the time interval, thereby reducing the rate at which the destination terminal sends a response message (such as the packet confirmation ACK message in the TCP protocol) to the message sender, so that the message sender reduces the rate of sending downlink messages to the target terminal when synchronizing the message sending rate.

[0106] The present embodiment, however, diverts the file download type messages so that they reach the destination ONU device and the ONU device of the second dormitory respectively, and then are transmitted from the ONU device of the second dormitory to the destination ONU device through the local area network (through the switch, not through the access cloud gateway), and finally reach the destination terminal, so that the destination terminal can immediately return a response message to the message sender, thereby maintaining the bandwidth limit for the first dormitory and utilizing the idle bandwidth of the second dormitory to increase the speed of file downloading for the first user and prevent the file downloading of the first user from affecting the network usage of other users in the first dormitory.

[0107] Embodiment 2:

[0108] The present invention is based on the method described in Example 1, combined with specific application scenarios, and uses technical descriptions in related scenarios to illustrate the implementation process of the present invention in characteristic scenarios.

[0109] This embodiment uses Fig.11 Taking the campus network application scenario shown as an example, the campus network is connected in the form of a new metropolitan area network. The campus network multi-terminal roaming authentication-free method described in this embodiment specifically includes:

[0110] First, in order to adapt to FTTR (Fiber to the Room) networking, PPPOE+ information is introduced. In order to make the account terminal switch links between optical modems without perception, multiple ONUs use the same SSID. Under normal circumstances, mobile terminal devices use wireless networks to access the Internet. For the security of the network, virtual MACs will be used. Therefore, when switching wireless networks, terminals generally switch to different MACs to access the Internet. When the SSID name of the wireless network is the same, the same terminal device, although switching under different ONUs, cannot perceive the change of the wireless network, and thus uses the same MAC to access the Internet. That is, setting all the optical modems on campus to the same SSID can ensure that the terminal MAC remains unchanged when traveling under different links.

[0111] However, in actual use, the ONUID carried in the option 82 information of the Dynamic Host Configuration Protocol (DHCP) changes frequently, so the PPPOE+ information of the account dial-up changes synchronously. After sensing the change in PPPOE+ information, the IOMP platform will send down the account redial interface, that is, the user terminal switches ONU frequently, PPPOE+ often changes, triggering frequent redialing, network instability, and high equipment pressure. In order to solve this problem, option82_sensitive is marked as 0 under the campus or QINQ, indicating that it is insensitive to the option 82 field, and 1 indicates sensitivity, that is, when the user terminal switches ONU, the cloud gateway receives a change in the option 82 field in the DHCP message. Since the QINQ link is marked as insensitive, there is no need to re-dial PPPOE, so as to ensure that the user terminal switches ONU, the PPPOE+ information remains unchanged, and does not frequently redial.

[0112] In the prior art, the LAN address pool only supports one C segment at most, that is, 250 terminals, which results in too limited resources and great difficulty in operation and maintenance; that is, the address pool under a QINQ only supports one C segment, and the address pool resources are insufficient. In order to solve this problem, this embodiment expands the QINQ address pool to the B segment, specifically:

[0113] IOMP configures the address pool of a LAN network as a B segment; the access virtual wireless terminal access device (Virtual Customer Premise Equipment, referred to as: vCPE) divides the configured B segment IP into multiple C segments for IP allocation (the mask is fixed to 24 bits, and each C segment corresponds to a gateway IP); the virtual private network (Virtual Private Network, referred to as: VPN) sets an identifier QinQ to allow the maximum number of NAT resources (NATIP+port_range) to be used; the uplink message comes through LANVNI+QINQ+MAC (LANVNI+QINQ here refers to the VNI identifier of the actual ONU device and the QinQ information of the actual ONU device) to apply for the address pool IP. When the number of terminals is greater than 250, the cloud gateway will automatically divide the next C segment network, so that every terminal in the school can get the same IP under QINQ. When the SSID remains unchanged, users can achieve free authentication; the business vSwitch allocates NATIP+port_range to users according to the QINQ under VPN. When there are too many user terminals, the number of NATIP+port_range can be dynamically adjusted.

[0114] After completing the above settings, Fig.12 As shown, it is assumed that accountA has dormitory building 1, teaching building 1, teaching building 2, library, gymnasium and teacher's building in the main activity venues of the school. The user of accountA selects these activity venues on the binding page (each activity venue corresponds to a roaming sub-area), generates and binds the corresponding roaming group, and accountB has dormitory building 2, teacher's building, gymnasium, library, teaching building 2 and teaching building 3 in the main activity venues of the school. Similarly, the user of accountB selects these activity venues on the binding page, generates and binds the corresponding roaming group; then the links can be divided into 2 groups (i.e., the roaming groups in Example 1) according to the attributes of the students, forming an account+VNIQINQ relationship table (i.e., the roaming group information table item and the account roaming information table item are combined); one account supports 3 terminal devices, forming an account+mac relationship table (i.e., the account roaming information table item in Example 1).

[0115] When the terminal mac1 of accountA passes the portal authentication for the first time in dormitory building 1, other devices mac2 and mac3 can be registered on the portal page; the portal server notifies the management platform to send the pre-authentication policy of accountA and terminal devices mac2 and mac3 to the cloud gateway in advance.

[0116] In actual use, there may be the following situations:

[0117] (1) When user accountA uses mac2 to access the Internet in the dormitory, the cloud gateway vSwitch receives a message of LANVNI+QINQ4+LAN_EVPN_Group, queries the rulein (i.e., the evpn transfer rule in the cloud gateway), and forwards the message to the vCPE. The vCPE queries the authentication table and finds that the mac has been authenticated and directly releases it. The LANVNI+QINQ4+LAN_EVPN_Group of the message (i.e., the second uplink message) is replaced with WANVNI+QINQ4+WAN_EVPN_Group (after the replacement, the third uplink message is obtained) and sent from the wan port. The VNI identifier and QinQ information (i.e., LANVNI+QINQ4+WAN_EVPN_Group) of the actual ONU device are first replaced with the WAN port. Q4) is converted into the virtual VNI identifier and virtual QinQ information of the corresponding roaming group virtual ONU device, and then the virtual VNI identifier and virtual QinQ information are used to find the corresponding WAN side VNI identifier and WAN side QinQ information (i.e. WANVNI+QINQ4). After receiving the message, vSwitch queries the ruleout (i.e. the outbound rule in the access cloud gateway) table and sends the message to the network side, so that there is no need for repeated authentication and direct access to the network; among them, LAN_EVPN_Group is the link from the terminal to the cloud gateway (also called a tunnel or EPVN instance), and WAN_EVPN_Group represents the link from the cloud gateway to Bras, which is used to establish an SRv6 tunnel to transmit data packets from the terminal to the cloud gateway and from the cloud gateway to Bras. That is, according to the binding relationship between qinq and Evpn_Group, a rulein / ruleout forwarding table will be formed inside the cloud gateway. After the uplink message arrives at the cloud gateway from the terminal, the lan side rulein is queried and forwarded to vcpe. After vcpe processes it, it is forwarded to vsw to encapsulate the srv6 tunnel header. After querying the wan side ruleout, it is forwarded to bras. After the downlink message is transferred to the cloud gateway, the wan side tunnel rulein is also queried and transferred to vcpe. After vcpe processes it, it is forwarded to vsw to encapsulate the srv6 tunnel header. After querying the lan side ruleout, it is transferred to the terminal.

[0118] (2) When user accountA uses mac2 to move to the library to surf the Internet, the cloud gateway vSwitch receives the message of LANVNI+QINQ6+LAN_EVPN_Group, queries the rulein forwarding table, and forwards the message to the vCPE. The vCPE queries the authentication table and finds that the mac has been authenticated and the account is accountA. It queries the account+VNIQINQ table to find user group 1. The current terminal tunnel has moved from the dormitory to the library and switched the physical link, but it is still in group 1 and does not need to be re-authenticated. The LANVNI+QINQ6+LAN_EVPN_Group of the message is directly replaced with WANVNI+QINQ6+WAN_EVPN_Group and sent from the wan port. After receiving the message, the vSwitch queries the ruleout table and sends the message to the network side.

[0119] (3) When user accountA uses terminal device mac2 to move to teaching building 3 to access the Internet, the cloud gateway vSwitch receives a message of LANVNI+QINQ3+LAN_EVPN_Group, queries the rulein forwarding table, and forwards the message to the vCPE. The vCPE queries the authentication table and finds that the mac has been authenticated and the account is accountA. It queries the account+VNIQINQ table and finds that the link VNI+QINQ3 is not in group 1. The cloud gateway redirects the traffic to the portal page. The terminal will pop up a window asking whether to trust the network. After clicking trust, the portal server notifies the management platform to incrementally send accountA+VNIQINQ3 to group 1 (that is, add the sub-area of ​​teaching building 3 to the roaming group bound to user accountA). The subsequent process is based on the same concept as step (2), that is, re-determine whether accountA has been authenticated in the roaming group, and then perform subsequent processing.

[0120] (4) User accountA uses terminal device mac2 to move to a network outside the campus, but the SSID is the same as that of the school. The cloud gateway vSwitch receives the message of LANVNIx+QINQx+LAN_EVPN_Group. According to the QinQ query, it is found that the currently connected ONU device is not an ONU device within the campus. It can be determined that user accountA is outside the campus and redirected to the interception page. The terminal will pop up a window prompting "Suspicious network, Internet access is prohibited!".

[0121] (5) When user accountA uses mac4 to access the Internet in the dormitory, the cloud gateway vSwitch receives a message of LANVNI+QINQ4+LAN_EVPN_Group, queries the rulein forwarding table, and forwards the message to the vCPE. The vCPE queries the authentication table and finds that the mac is not authenticated. It redirects the message to the portal server and asks the unknown mac to find an account for authentication. If the number of macs under user accountA is less than 3, it is directly authenticated to access the Internet; if it is equal to 3, it is necessary to manually remove a terminal and add the new terminal to the authentication table.

[0122] Embodiment 3:

[0123] like Fig.13 , which is a schematic diagram of the architecture of a campus network multi-terminal roaming authentication-free device according to an embodiment of the present invention. The campus network multi-terminal roaming authentication-free device according to this embodiment includes one or more processors 21 and a memory 22. Fig.13 A processor 21 is taken as an example.

[0124] The processor 21 and the memory 22 may be connected via a bus or other means. Fig.13 The example of connecting through bus is taken in the following.

[0125] The memory 22, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs and non-volatile computer executable programs, such as the campus network multi-terminal roaming authentication-free method in Example 1. The processor 21 executes the campus network multi-terminal roaming authentication-free method by running the non-volatile software programs and instructions stored in the memory 22.

[0126] The memory 22 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage devices. In some embodiments, the memory 22 may optionally include a memory remotely arranged relative to the processor 21, and these remote memories may be connected to the processor 21 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0127] The program instructions / modules are stored in the memory 22, and when executed by the one or more processors 21, the campus network multi-terminal roaming authentication-free method in the above-mentioned embodiment 1 is executed.

[0128] It is worth noting that the information interaction, execution process, etc. between the modules and units within the above-mentioned devices and systems are based on the same concept as the processing method embodiment of the present invention. The specific contents can be found in the description of the method embodiment of the present invention and will not be repeated here.

[0129] A person skilled in the art may understand that all or part of the steps in the various methods of the embodiments may be completed by instructing related hardware through a program, and the program may be stored in a computer-readable storage medium, and the storage medium may include: a read-only memory (ROM), a random access memory (RAM), a disk or an optical disk, etc.

[0130] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the protection scope of the present invention.

Claims

1. A campus network multi-terminal roaming authentication-free method, characterized in that: include: A binding page entrance is reserved in the portal page, so that after the user successfully authenticates and logs in using the corresponding terminal, the user can enter the binding page from the binding page entrance, enter the MAC addresses of multiple terminals owned by the user on the binding page, and select one or more roaming sub-areas; According to the MAC addresses of the multiple terminals and the selected roaming sub-areas, a roaming group is set for the multiple terminals in the access cloud gateway; wherein the roaming group includes the MAC addresses of the multiple terminals, relevant information of the selected multiple roaming sub-areas, relevant information of each actual ONU device in the selected multiple roaming sub-areas, and relevant information of the unique virtual ONU device of the roaming group; When the first ONU device receives the first uplink message from the first terminal, it adds relevant information of the first ONU device to the first uplink message, generates a second uplink message, and sends the second uplink message to the access cloud gateway; wherein the first uplink message also carries the mac address of the first terminal; The access cloud gateway determines whether the first user is an authenticated user in the roaming area where the first ONU device is located according to the MAC address of the first terminal carried in the second uplink message, the relevant information of the first ONU device, and each roaming group; wherein the first user is the user to which the first terminal belongs; If it is determined that the first user is an authenticated user in the roaming area where the first ONU device is located, the second uplink message is encapsulated into a third uplink message recognizable by the wide area network according to the relevant information of the virtual ONU device in the roaming group to which the first ONU device belongs, and the third uplink message is transmitted to the network.

2. The campus network multi-terminal roaming authentication-free method according to claim 1, characterized in that: The relevant information of the actual ONU device includes the VNI identification of the actual ONU device and the QinQ information of the actual ONU device; the relevant information of the virtual ONU device includes the virtual VNI identification and the virtual QinQ information; The access cloud gateway includes a virtual switch and a virtual client device, and the step of setting a roaming group for the multiple terminals in the access cloud gateway according to the MAC addresses of the multiple terminals and the selected roaming sub-areas specifically includes: Storing roaming group information items, ONU device information items, and account roaming information items in the virtual client device; The roaming group information table entry stores the ID number of each roaming group, the ID number of each roaming sub-area, and the virtual VNI identifier and virtual QinQ information corresponding to each roaming group; The ONU device information table item stores the VNI identification of each actual ONU device, the QinQ information of each actual ONU device, and the ID number of the roaming sub-area to which each actual ONU device belongs; The account roaming information table entry stores the MAC addresses of the terminals bound to the user, the user's account information, and the ID number of the bound roaming group.

3. The campus network multi-terminal roaming authentication-free method according to claim 2, characterized in that: The access cloud gateway determines, according to the MAC address of the first terminal carried in the second uplink message, the relevant information of the first ONU device, and each roaming group, whether the first user is an authenticated user in the roaming area where the first ONU device is located, specifically including: The virtual switch receives the second uplink message, and forwards the second uplink message to the virtual client device; The virtual client device finds the first roaming group bound to the first terminal from the account roaming information entry according to the MAC address of the first terminal carried in the second uplink message, and finds the first account information of the user to which the first terminal belongs; Acquire, from the ONU device information table entry, a first roaming sub-area to which the first ONU device belongs, according to the VNI identifier of the first ONU device and the QinQ information of the first ONU device carried in the second uplink message; searching, according to the roaming group information table item, whether the first roaming group includes the first roaming sub-area, and if it is found that the first roaming group includes the first roaming sub-area, searching whether there is historical login information of the first account information in the first roaming group; If the historical login information exists, it is determined that the first user is an authenticated user in the roaming area where the first ONU device is located.

4. The campus network multi-terminal roaming authentication-free method according to claim 3, characterized in that: The historical login information is recorded when the terminal bound to the user performs historical authentication and login in the roaming sub-area included in the first roaming group, and specifically includes: When the virtual client device determines that the first user is not an authenticated user in the roaming area where the first ONU device is located, redirecting the second uplink message to the portal server so that the portal server feeds back a portal authentication page to the first terminal; After the first terminal successfully logs in and authenticates on the portal authentication page, the portal server returns an authentication success message to the virtual client device; wherein the authentication success message carries the account information used for authentication, the VNI identifier of the ONU device currently accessed by the first terminal, and the QinQ information of the ONU device currently accessed by the first terminal; The virtual client finds the corresponding roaming sub-area from the ONU device information table item according to the VNI identifier of the ONU device currently accessed by the first terminal and the QinQ information of the ONU device currently accessed by the first terminal; and searches the roaming group including the roaming sub-area from the roaming group information table item according to the roaming sub-area; The ID number of the roaming group and the account information are recorded as historical login information in the authentication table; wherein, for one account information, only the latest historical login information is recorded in the authentication table.

5. The campus network multi-terminal roaming authentication-free method according to claim 2, characterized in that: The step of encapsulating the second uplink message into a third uplink message identifiable by a wide area network according to the virtual ONU device related information in the roaming group to which the first ONU device belongs specifically includes: Find the corresponding WAN side VNI identifier and WAN side QinQ information according to the virtual ONU device related information in the roaming group to which the first ONU device belongs; The WAN side VNI identifier and the WAN side QinQ information are used to replace the virtual ONU device related information in the second uplink message to generate the third uplink message.

6. The campus network multi-terminal roaming authentication-free method according to claim 1, characterized in that: The method also includes: IOMP sets an address pool for each roaming group; the addresses in each address pool extend to segment B; According to the MAC address of the first terminal and the related information of the first ONU device carried in the second uplink message, a corresponding address is taken from the address pool of the corresponding roaming group and allocated to the first terminal.

7. The campus network multi-terminal roaming authentication-free method according to claim 1, characterized in that: The method also includes: setting the same SSID for all ONU devices located in a roaming area.

8. The campus network multi-terminal roaming authentication-free method according to claim 1, characterized in that: The method also includes: Set the option82_sensitive value of the roaming area in the access cloud gateway to 0 so that when the option82 field in the message sent by different ONU devices changes, the dial-up is not re-performed.

9. A non-volatile computer storage medium, characterized in that: The computer storage medium stores computer executable instructions, which are executed by one or more processors to complete the campus network multi-terminal roaming authentication-free method described in any one of claims 1-8.

10. A device for multi-terminal roaming without authentication in a campus network, characterized in that: include: at least one processor; And, a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the processor to execute the method for multi-terminal roaming in a campus network without authentication as described in any one of claims 1-8.

Citation Information

Patent Citations

  • Method and device for preventing re-authentication of roaming user

    CN102075904A

  • Network access control method and system

    CN102984173A

  • Authentication-free roaming method and device

    CN117528495A

  • System and method for implementing centralized configuration and management for ONU wireless function

    WO2016034120A1

  • Method and system for network certification

    WO2017092501A1